CVE-2026-46331
In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb_ensure_writable() inside the per-key loop where the actual write offset is known, and add overflow checking on the offset arithmetic. For negative offsets (e.g. Ethernet header edits at ingress), use skb_cow() to COW the headroom instead. Guard offset_valid() against INT_MIN, where negation is undefined.
- Affected products
- Linux Kernel, Rocky Linux
- Linux Linux Kernel
- < 4.20, 5.5, 5.11, 5.16, 5.18, 6.12.94, 6.18.36, 7.0.13, 7.1
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.5% (42th percentile)
- Weakness
- CWE-190, CWE-787
- NVD status
- Modified
- Published
- 2026-06-16
13 known exploits for CVE-2026-46331
Proof-of-concept code and exploit modules indexed by Sploitus